Your company is participating in a Cyber Security Education Program.


This CERB Phishing Attack included the following social engineering techniques:


  1. Topical subject (CERB) to be consistent with current news.
  2. Sense of urgency to act so you don't lose your money.
  3. Government of Canada logo to appear legitimate.
  4. Multiple languages to appear official.
  5. Links and sender names masked with cra-arc/gov.ca to appear correct.


How to spot this was a phishing email:


  1. Was this an email you expected to receive? No - Be cautious
  2. Is it asking you to do something before some urgent deadline? - Yes - This is a typical tactic used
  3. The sender named "CERB Eligibility" email address was suspicious (do-not-reply@online-statistics.site)
  4. The link provided https://cerb-2020-eligibility.gov.ca/register (if checked/mouse hover) was directing to http://cra-arc.lang-en.ca/...


Note: Government of Canada website is canada.ca


“An employee is either an asset to your cyber security or a risk.”